kernel CVE-2022-33742
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.9.0
Patched versions
1.9.0
kernel-5.15
(bottlerocket)
< 1.9.0
1.9.0
kernel-5.4
(bottlerocket)
< 1.9.0
1.9.0
Block and network PV device frontends don’t zero memory regions before sharing them with the backend, and the granularity of the grant table doesn’t allow sharing less than a 4K page. This leads to unrelated data residing in the same 4K page as data shared with a backend being accessible by that backend.